6 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2026-59310 is a critical directory traversal vulnerability affecting the Syslog server component of VMware vCenter Server.
The vulnerability is caused by improper restriction of pathname resolution, allowing a remote attacker with network access to traverse outside the intended directory scope and access unintended resources. No authentication or user interaction is required to exploit the flaw.
Successful exploitation may allow arbitrary code execution on the vCenter server, potentially leading to full compromise of the virtualization management environment. Broadcom has confirmed active exploitation of CVE-2026-59310 in the wild.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Directory Traversal Leading to Remote Code Execution in VMware vCenter Syslog Server
Identifier: CVE-2026-59310
PoC or Exploitation:
CVSS Score: 9.8 (Critical, CVSS v3.1)
Update / Patch:
- VMware vCenter 9.1: 9.1.0.0300
- VMware vCenter 9.0: 9.0.2.0100
- VMware vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the deployed branch
Description:
Mitigation Recommendation: